{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wp-ultimate-review--2.4.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wp_ultimate_review_project:wp_ultimate_review:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-92235"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP Ultimate Review (\u003c= 2.4.2)"],"_cs_severities":["high"],"_cs_tags":["wordpress","vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to and including 2.4.2. The flaw exists because the software fails to properly validate user-supplied input before passing it to the 'do_shortcode' function. An authenticated attacker with subscriber-level permissions or higher can exploit this lack of validation to trigger arbitrary shortcode execution. This vulnerability is significant as it allows low-privileged users to perform unauthorized actions or gain access to sensitive information typically restricted by the application, depending on the available shortcodes registered within the WordPress environment. Organizations using this plugin should evaluate their use of shortcodes and upgrade to a patched version once available.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated subscriber to execute arbitrary shortcodes, potentially leading to unauthorized data disclosure, privilege escalation, or unauthorized modifications within the WordPress site depending on the installed plugins and theme capabilities.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor WordPress administrative activity logs for unexpected shortcode usage by subscriber-level accounts.\u003c/li\u003e\n\u003cli\u003eReview the list of active plugins to identify those that register potentially sensitive or administrative shortcodes.\u003c/li\u003e\n\u003cli\u003eUpdate the WP Ultimate Review plugin to the latest version once a patch is released to remediate CVE-2026-92235.\u003c/li\u003e\n\u003cli\u003eAudit subscriber-level account permissions to ensure they are constrained from accessing sensitive plugin configurations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T08:34:39Z","date_published":"2026-09-22T08:34:39Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-92235/","summary":"The WP Ultimate Review plugin for WordPress contains an arbitrary shortcode execution vulnerability (CVE-2026-92235) that allows authenticated attackers with subscriber-level access to execute arbitrary shortcodes.","title":"Arbitrary Shortcode Execution in WP Ultimate Review","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-92235/"}],"language":"en","title":"CraftedSignal Threat Feed - WP Ultimate Review (\u003c= 2.4.2)","version":"https://jsonfeed.org/version/1.1"}